[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 21:33:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a8ca3df4 by Salvatore Bonaccorso at 2026-09-26T22:33:00+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -250,43 +250,43 @@ CVE-2026-100631 (Parse Server is an open source backend server. In versions prio
 CVE-2026-100630 (AVideo contains a stored cross-site scripting vulnerability in the vid ...)
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-100629 (Capgo (capgo.app backend) before 12.127.5 contains an authorization fl ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100628 (capgo.app before 12.128.12 fails to enforce an organization's API key  ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100627 (Capgo (Cap-go/capgo.app) server backend Supabase functions contain an  ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100626 (capgo through 12.128.2 contains an insecure direct object reference vu ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100625 (Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/fu ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100624 (Capgo.app before 12.264.5 does not enforce upload expiry or build life ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100623 (Capgo (capgo.app) exposes the legacy membership table public.org_users ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100622 (capgo.app through 12.129.0 fails to verify deletion status when servin ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100621 (Capgo (capgo.app) contains an incomplete access-control/content-lock e ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100620 (Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an ov ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100619 (Capgo (capgo.app) blocks direct user inserts into the public.manifest  ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100618 (Capgo (capgo.app) is affected by an authorization flaw in the app icon ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100617 (Cap-go capgo.app fails to validate that principals in channel_permissi ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100616 (capgo.app is an over-the-air update platform for Capacitor apps. In al ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100615 (Cap-go capgo.app before 12.267.1 fails to validate target API key priv ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100614 (Capgo before 12.244.1 contains a cross-tenant integrity vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100613 (capgo.app is an over-the-air (OTA) update platform for Capacitor apps. ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100612 (Capgo (capgo.app) through version 12.261.0 contains an incomplete acce ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100611 (Capgo (capgo.app backend, versions \u2264 12.261.0) improperly restric ...)
-	TODO: check
+	NOT-FOR-US: Cap-go
 CVE-2026-100610 (Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH ...)
 	NOT-FOR-US: Flowise
 CVE-2026-100609 (Flowise (npm packages `flowise` and `flowise-components`) through 3.1. ...)
@@ -310,15 +310,15 @@ CVE-2026-100601 (ClawHub (openclaw/clawhub) application/backend contains a serve
 CVE-2026-100600 (ClawHub (the openclaw/clawhub application/backend) does not bind anony ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100315 (A vulnerability was detected in mathurvishal CloudClassroom-PHP-Projec ...)
-	TODO: check
+	NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100314 (A security vulnerability has been detected in mathurvishal CloudClassr ...)
-	TODO: check
+	NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100313 (A weakness has been identified in mathurvishal CloudClassroom-PHP-Proj ...)
-	TODO: check
+	NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100312 (A security flaw has been discovered in mathurvishal CloudClassroom-PHP ...)
-	TODO: check
+	NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-100311 (A vulnerability was identified in mathurvishal CloudClassroom-PHP-Proj ...)
-	TODO: check
+	NOT-FOR-US: mathurvishal CloudClassroom-PHP-Project
 CVE-2026-XXXX [GHSA-3q6v-r5mr-hxv8: Fix quadratic-time table start detection on long paragraphs]
 	- php-league-commonmark 2.10.3-1
 	NOTE: https://github.com/thephpleague/commonmark/security/advisories/GHSA-3q6v-r5mr-hxv8
@@ -545,7 +545,7 @@ CVE-2026-100546 (OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 20
 CVE-2026-100545 (OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100544 (openclaw's @openclaw/voice-call package before 2026.8.1 launches the c ...)
-	TODO: check
+	NOT-FOR-US: openclaw/voice-call
 CVE-2026-100543 (OpenClaw (npm package openclaw) before 2026.8.1 could include determin ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100542 (OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 ...)
@@ -569,9 +569,9 @@ CVE-2026-100534 (OpenClaw versions before 2026.8.1 contain an authorization bypa
 CVE-2026-100533 (OpenClaw versions before 2026.8.1 contain a path traversal vulnerabili ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100532 (@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login to ...)
-	TODO: check
+	NOT-FOR-US: penclaw/whatsapp Node.js module
 CVE-2026-100531 (The @openclaw/slack npm package before 2026.8.1 contains an authorizat ...)
-	TODO: check
+	NOT-FOR-US: openclaw/slack npm package
 CVE-2026-100530 (OpenClaw versions before 2026.8.1 fail to bind working directory conte ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100529 (OpenClaw versions before 2026.8.1 contain an authorization scope widen ...)
@@ -585,15 +585,15 @@ CVE-2026-100526 (OpenClaw's Discord integration (npm package @openclaw/discord)
 CVE-2026-100525 (The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prom ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-100524 (Cotonti through 1.0.0 contains a cross-site request forgery vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Cotonti CMS
 CVE-2026-100523 (Cotonti through 1.0.0 contains an open redirect vulnerability in messa ...)
-	TODO: check
+	NOT-FOR-US: Cotonti CMS
 CVE-2026-100522 (Cotonti through 1.0.0 contains a reflected cross-site scripting vulner ...)
-	TODO: check
+	NOT-FOR-US: Cotonti CMS
 CVE-2026-100521 (Cotonti through 1.0.0 contains a reflected cross-site scripting vulner ...)
-	TODO: check
+	NOT-FOR-US: Cotonti CMS
 CVE-2026-100520 (Laranode versions before 1.2.1 contain a path traversal vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Laranode
 CVE-2026-100505 (Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read  ...)
 	TODO: check
 CVE-2026-100504 (Ghidra versions through 12.1.4 contain a stack-based out-of-bounds wri ...)
@@ -601,25 +601,25 @@ CVE-2026-100504 (Ghidra versions through 12.1.4 contain a stack-based out-of-bou
 CVE-2026-100503 (Ghidra versions through 12.1.4 contain a heap use-after-free vulnerabi ...)
 	TODO: check
 CVE-2026-100502 (Flame through 2.4.0 contains an insufficient session expiration vulner ...)
-	TODO: check
+	NOT-FOR-US: Flame
 CVE-2026-100501 (Flame through 2.4.0 contains an improper restriction of excessive auth ...)
-	TODO: check
+	NOT-FOR-US: Flame
 CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation bypass vulner ...)
 	TODO: check
 CVE-2026-100418 (Flame through 2.4.0 contains an information exposure vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Flame
 CVE-2026-100417 (RustDesk before 1.5.0 on Windows fails to enforce the one-way file tra ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-100391 (MediaFlow Proxy through 2.4.9 contains a server-side request forgery v ...)
-	TODO: check
+	NOT-FOR-US: MediaFlow Proxy
 CVE-2026-100390 (Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addres ...)
-	TODO: check
+	NOT-FOR-US: Zoraxy
 CVE-2026-100389 (GestSup versions before 3.2.61 contain a remote code execution vulnera ...)
-	TODO: check
+	NOT-FOR-US: GestSup
 CVE-2026-100388 (RustDesk versions before 1.5.0 fail to properly validate file transfer ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-100387 (pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerab ...)
-	TODO: check
+	NOT-FOR-US: pgPointcloud
 CVE-2026-100383 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-100382 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
@@ -637,13 +637,13 @@ CVE-2026-100377 (Exposure of Sensitive Information to an Unauthorized Actor vuln
 CVE-2026-100376 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	TODO: check
 CVE-2026-100373 (OpenMetadata through 2.0.2 contains a server-side request forgery vuln ...)
-	TODO: check
+	NOT-FOR-US: OpenMetadata
 CVE-2026-100372 (ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: ClipBucket
 CVE-2026-100369 (CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are ...)
-	TODO: check
+	NOT-FOR-US: CliInvoke
 CVE-2026-100368 (CliInvoke is a .NET library for invoking command-line programs, and it ...)
-	TODO: check
+	NOT-FOR-US: CliInvoke
 CVE-2026-100310 (GNU libextractor before 1.16 loads plugins from an untrusted search pa ...)
 	- libextractor 1:1.17-1
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/25/25
@@ -1290,33 +1290,33 @@ CVE-2026-13179 (The WP Maps \u2013 Google Maps,OpenStreetMap,Mapbox,Store Locato
 CVE-2026-12037 (The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerab ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-100306 (TDuck survey form through 6.0 fails to validate write passwords on sub ...)
-	TODO: check
+	NOT-FOR-US: TDuck survey
 CVE-2026-100305 (TDuck survey form through 6.0 fails to enforce form fill-in restrictio ...)
-	TODO: check
+	NOT-FOR-US: TDuck survey
 CVE-2026-100304 (TDuck survey form 6.0 contains an information disclosure vulnerability ...)
-	TODO: check
+	NOT-FOR-US: TDuck survey
 CVE-2026-100303 (TDuck survey form through 6.0 lacks authorization checks on FormThemeC ...)
-	TODO: check
+	NOT-FOR-US: TDuck survey
 CVE-2026-100248 (The Rattadan Cosmowarp smart contract before 56c6147 can have a compar ...)
-	TODO: check
+	NOT-FOR-US: Rattadan Cosmowarp smart contract
 CVE-2026-100237 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-100230 (Input Leap (aka input-leap) through 3.0.3, when the non-default --enab ...)
 	TODO: check
 CVE-2026-100192 (X-SpringBoot through 6.0 exposes appKey and appSecret credentials in t ...)
-	TODO: check
+	NOT-FOR-US: X-SpringBoot
 CVE-2026-100190 (The AIL Framework crawler splash domain page (showDomain.html) is vuln ...)
-	TODO: check
+	NOT-FOR-US: AIL Framework
 CVE-2026-100187 (The Onion module in AIL Framework contained a performance shortcut in  ...)
-	TODO: check
+	NOT-FOR-US: AIL Framework
 CVE-2026-100177 (The AIL Framework crawler task creation API (api_add_crawler_task) con ...)
-	TODO: check
+	NOT-FOR-US: AIL Framework
 CVE-2026-100176 (The AIL Framework's username timeline feature is vulnerable to stored  ...)
-	TODO: check
+	NOT-FOR-US: AIL Framework
 CVE-2026-100174 (The AIL Framework tag selector component (var/www/static/js/tags.js) i ...)
-	TODO: check
+	NOT-FOR-US: AIL Framework
 CVE-2026-100172 (The AIL Framework (ail-project/ail-framework) contains a stored cross- ...)
-	TODO: check
+	NOT-FOR-US: AIL Framework
 CVE-2025-51457 (D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command in ...)
 	NOT-FOR-US: D-Link
 CVE-2025-14814 (The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Sto ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ca3df45ae7dfde4253b76e99d7d1b76adad2f6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8ca3df45ae7dfde4253b76e99d7d1b76adad2f6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/4f0281e7/attachment.htm>


More information about the debian-security-tracker-commits mailing list